CVE-2026-41461 - Vulnerability Analysis
HighCVSS: 8.5Last Updated: April 23, 2026
SocialEngine - Server-Side Request Forgery
Published: April 23, 2026Updated: April 23, 2026Remote Exploitable
Overview
SocialEngine <= 7.8.0 contains a server-side request forgery caused by unsanitized user input in the /core/link/preview endpoint's uri parameter, letting authenticated attackers make arbitrary HTTP requests, exploit requires authentication.
Severity & Score
Severity: High
CVSS Score: 8.5
Impact
Authenticated attackers can make the server send arbitrary HTTP requests, enabling internal network enumeration and access to restricted services.
Mitigation
Update to the latest version beyond 7.8.0.
References
Related Resources
Details
- CVE ID
- CVE-2026-41461
- Severity
- High
- CVSS Score
- 8.5
- Type
- server_side_request_forgery
- Status
- new
CWE
- CWE-918
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N